Page Summary
-
Administrators can list users with account access by querying
CustomerUserAccessentities using Google Ads Query Language. -
The provided code examples demonstrate how to retrieve user access information and modify a user's access role.
-
You need to identify the user's access details, including their user ID, before you can modify their access role.
As an administrator, you can manage user access levels and roles for your Google Ads accounts. You can retrieve and update user roles, send user invitations, and terminate user access to an account using the Google Ads API. Learn more about account access levels.
To manage user access, the calling user or service account must have ADMIN
access to the target account.
Invite users
To invite a new user to access an account, use the
CustomerUserAccessInvitationService to create and send an invitation (see
Manage user access invitations). Once the user accepts the
invitation, they will appear as a confirmed user under CustomerUserAccess.
Retrieve user roles
You can get the list of users with access to an account by building a
Google Ads Query Language statement to query all the
CustomerUserAccess entities associated
with a customer ID. Here is a typical query:
SELECT
customer_user_access.user_id,
customer_user_access.email_address,
customer_user_access.access_role,
customer_user_access.access_creation_date_time,
customer_user_access.inviter_user_email_address
FROM customer_user_access
Modify user roles
To update an existing user role, call
CustomerUserAccessService.MutateCustomerUserAccess using the UPDATE
operation. When modifying a user role, you must provide:
- The resource name of the
CustomerUserAccessentity to modify, in the formatcustomers/{customer_id}/customerUserAccesses/{user_id}. - The new user role in
access_role. - An
update_mask(FieldMask) specifyingaccess_role.
Remove users
To terminate a user's access to the account, call
CustomerUserAccessService.MutateCustomerUserAccess with a REMOVE
operation specifying the resource name
(customers/{customer_id}/customerUserAccesses/{user_id}).
Multi-party approval for access changes
If a multi-party approval request is triggered when calling
MutateCustomerUserAccess:
- The
MutateCustomerUserAccessResultobject (contained within theresultfield ofMutateCustomerUserAccessResponse) will populate themulti_party_auth_reviewfield with the resource name of the pending review requiring approval. - The
resource_namefield onMutateCustomerUserAccessResultwill not be populated. - The pending review request can be approved or rejected by a second
administrator using the
MultiPartyAuthReviewService.ResolveMultiPartyAuthReviewmethod. Refer to the multi-party approval guide to learn more.